You already can't do that since the abuser will just buy residential proxies.
CF seems to end up in the business of making problems worse, and selling the fix way too often. Before this, I had someone try to DDoS a webapp by setting up their own domain to proxy to my backend and running their attack traffic through CF. But that was easy, I could just block CF's IP range entirely as I don't use their reverse proxies.
If you work for an ISP you'll see it all the time. It's a constant fight to keep your subnet reputations high, which is hard when the subscribers don't care unless you shut off their service, but then your IP block still has a reputation issue to clean.